Courseiva

GSEC Windows Automation and Auditing Practice Question

You are a security consultant reviewing a Windows Server 2016 environment. The client wants to ensure that all administrative actions are logged and can be traced back to individual administrators. Currently, all administrators use a shared domain admin account. Which security control should you recommend to meet this requirement?

⚠ Common exam trap

The trap here is focusing on audit policy configuration when the real problem is the use of a shared account, which makes individual attribution impossible regardless of audit settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement separate administrative accounts for each administrator.

The core issue is that shared accounts prevent attribution. To trace administrative actions to individuals, each administrator must have a unique account. This ensures that audit logs record the specific user who performed each action. Other options address audit policy settings but do not solve the fundamental problem of shared credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a Group Policy Object to enable 'Audit process tracking' for all servers.

    Why it's wrong here

    Audit process tracking logs process creation and termination, which can help detect malicious activity, but it does not provide individual accountability for administrative actions. The logs would still show the shared account as the user context. Therefore, it does not meet the requirement to trace actions back to individual administrators.

  • ✗

    Enable the 'Audit: Force audit policy subcategory settings' policy.

    Why it's wrong here

    This policy ensures that advanced audit policy subcategory settings take precedence over legacy audit policies. It does not address the issue of shared accounts. While it improves audit consistency, it does not enable traceability to individual administrators because the account name logged would still be the shared account. Thus, it does not meet the requirement.

  • ✓

    Implement separate administrative accounts for each administrator.

    Why this is correct

    Using separate accounts ensures that each administrator's actions are logged under their unique account. This allows auditing and traceability. Shared accounts prevent attribution. By implementing individual accounts, you can track who performed which action. This is a fundamental principle of accountability and directly solves the scenario's requirement.

  • ✗

    Enable 'Audit: Shut down system immediately if unable to log security audits'.

    Why it's wrong here

    This policy forces the system to shut down if it cannot log an audit event, ensuring no auditable event is lost. However, it does not provide individual accountability. If administrators share an account, the logs still show the shared account name. This policy addresses audit reliability, not attribution, so it is not the correct recommendation.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.